The Hard Line: States That Now Prohibit AI Therapy
Most healthcare-AI writing treats regulation as friction — a compliance tax on an otherwise obvious deployment. In behavioral health that framing is simply wrong. Several states have decided, as a matter of statute, that certain uses of AI in mental health care are not permitted at any price, under any consent, with any disclaimer. If you own a therapy practice, the first question is not "how do we do this compliantly." It is "is this on the permitted list at all."
The clearest statement of the line is the Illinois Wellness and Oversight for Psychological Resources Act (HB 1806), signed and effective August 1, 2025. It bars AI from making independent clinical decisions, from communicating therapeutically with a client, from generating treatment recommendations without professional review, and from assessing a client's emotional state. It also bars marketing or advertising "AI therapy" services. Enforcement runs through the Illinois Department of Financial and Professional Regulation, with civil penalties up to $10,000 per violation — a per-violation figure that scales with your client panel, not with your intent. See the IDFPR announcement.
Nevada arrived at the same place by a different route. AB 406, signed June 5, 2025 and effective July 1, 2025, prohibits AI from providing — or representing that it provides — professional mental or behavioral health care. Licensed professionals may use AI administratively and supportively, and that is the whole of the permission.
Utah took the third path. HB 452, effective May 7, 2025, permits regulated mental health chatbots but conditions them on layered disclosure: a clear notice before first access, another after seven or more days of non-use, and another whenever the user asks. It adds advertising restrictions and bars selling individual health data without consent. Utah is the most permissive of the three and it is still a long way from "ship a chatbot and see what happens."
This is the same distinction the AMA makes when it insists on the term augmented intelligence — "a conceptualization of artificial intelligence that focuses on AI's assistive role, emphasizing that its design enhances human intelligence rather than replaces it." In June 2026 the AMA House of Delegates adopted policy stating that AI is an assistive tool rather than an autonomous decision-maker, and that transparency, accountability, and clinician oversight are required whenever AI is used in patient care. Behavioral health statutes have now written that principle into enforceable law.
Permitted vs Prohibited: The Table That Actually Decides Your Roadmap
Here is the useful part. The Illinois statute does not merely prohibit — it expressly permits AI for scheduling, billing, documentation, and ambient scribing, with written client consent required for supplementary uses. That permitted list is not a consolation prize. It is where a private practice actually loses its unbilled hours.
The table below is built on the Illinois line because Illinois is the strictest current statute and therefore the safest design target. It is not, however, a national rule. Nevada is close to identical in effect. Utah permits a narrow, disclosed chatbot category that Illinois does not. Several 2026 and 2027 laws are still being interpreted. Treat the left column as your roadmap and the right column as a hard stop, then run a state-by-state check before you enable anything in a new licensure jurisdiction.
| Green light — administrative, documentation, operations | Red light — clinical, therapeutic, evaluative |
|---|---|
| Appointment scheduling, reminders, waitlist backfill, cancellation and reschedule handling | Delivering therapy or counseling directly to a client, in text, voice, or avatar form |
| Insurance verification, benefits and eligibility checks, superbill generation, claims follow-up | Making an independent clinical decision, or issuing a treatment recommendation that no licensed professional reviews |
| Ambient documentation and note drafting that the clinician reads, edits, and signs | Detecting, scoring, or otherwise assessing a client's emotional state |
| Intake paperwork, consent delivery and tracking, records requests, release-of-information logistics | Producing a diagnosis, formulation, or therapeutic response that reaches the client unreviewed |
| Answering non-clinical questions: hours, location, fees, sliding scale, telehealth links, parking | Any interaction marketed or presented as 'AI therapy,' or as licensed, doctor-led, or clinician-guided care |
| Drafting clinician-facing summaries, letters, and referral packets for human review and signature | Continuing an interaction with a client in crisis instead of escalating immediately to a human |
| Outcome-measure administration logistics — sending, reminding, and filing standardized instruments | Interpreting those instruments and acting on the interpretation without a clinician in the loop |
Permitted versus prohibited AI use cases in a behavioral health private practice, modeled on the Illinois WOPR Act line. State-by-state, not uniform.
Why the left column is worth more than it looks
A solo or small-group therapy practice does not have a billing department, a front desk shift lead, or a credentialing analyst. It has a clinician doing all three jobs between sessions and after them. Scheduling, reminders, eligibility checks, superbills, claims follow-up, records requests, and note drafting are the entire administrative surface of the business — and every one of them is on the permitted side of the line.
The AMA's 2026 Physician AI Sentiment Report (n=1,692, fielded January 15 to February 2, 2026) found 81% of physicians now use AI professionally, up from 66% in 2024 and 38% in 2023, with roughly 70% locating AI's value in automating burnout drivers — documentation, chart review, prior authorization. That adoption curve is running almost entirely through the administrative layer, which is exactly where behavioral health law leaves the door open.
Deny by default. A behavioral health agent should have an allowlist of permitted intents and route everything else to a human — not a blocklist of prohibited ones. Blocklists fail open, and in this specialty failing open is a licensure problem, not a bug report.
— Frenchy Digital design principle
The State-by-State Map, 2025 Through 2027
A multi-state telehealth practice cannot answer this question once. The statutes differ in what they prohibit, who enforces them, and what a violation costs. The table below covers the measures that are in force or scheduled, with the enforcement mechanism attached — because the enforcement column is what determines your real exposure.
| Law | Status / effective date | What it restricts | Enforcement |
|---|---|---|---|
| Illinois — WOPR Act (HB 1806) | Signed and effective Aug 1, 2025 | Bars AI from independent clinical decisions, direct therapeutic communication, treatment recommendations without professional review, and emotional-state assessment. Bars marketing 'AI therapy.' Expressly permits scheduling, billing, documentation, and ambient scribing; supplementary uses need written client consent | IDFPR — civil penalty up to $10,000 per violation |
| Nevada — AB 406 | Signed Jun 5, 2025; effective Jul 1, 2025 | Prohibits AI from providing, or representing that it provides, professional mental or behavioral health care. Licensed professionals may use AI only administratively or supportively | State enforcement |
| Utah — HB 452 | Effective May 7, 2025 | Permits regulated mental health chatbots, with clear disclosure before first access, again after 7+ days of non-use, and whenever asked. Advertising restrictions; bars selling individual health data without consent | Utah Division of Consumer Protection |
| California — AB 489 | Effective Jan 1, 2026 | Bars AI from using terms, post-nominals, or design elements implying licensure — 'doctor,' 'M.D.,' 'nurse,' 'clinician-guided' and similar | Licensing boards — each use is a separate violation |
| California — SB 243 (companion chatbots) | Signed Oct 13, 2025; operative Jan 1, 2026 | Clear and conspicuous AI notification where a reasonable person could be misled into thinking they are talking to a human; suicide and self-harm crisis protocol required; annual reporting from Jul 1, 2027 | Private right of action — actual damages or $1,000 per violation, plus fees |
| Delaware — HB 191 | Passed Apr 23, 2026 | No nonhuman entity, including an AI agent, may be licensed or certified as a nurse, APRN, LPN, physician, or PA, or use those protected titles | Licensing boards |
| Arizona — Board of Behavioral Health Examiners rule | Effective Jan 1, 2027 | Documented informed consent required before using AI, machine learning, or human-simulation modalities | AZ Board of Behavioral Health Examiners |
| Maine — LD 2082 | 2026 wave | Limits mental health professionals to administrative AI; consent required for ambient listening | State enforcement |
State restrictions on AI in mental and behavioral health, as of August 2026. Where an effective date is shown as "2026 wave," we could not verify a specific date to a primary source — confirm with counsel before relying on it.
The pipeline is longer than the list of laws already in force, and 2027 is where most of it lands.
| State | Measure | Effective date |
|---|---|---|
| Tennessee | SB 1580 | July 1, 2026 |
| Oregon | SB 1546 | January 1, 2027 |
| Idaho | Conversational AI Safety Act | July 1, 2027 |
| Nebraska | Conversational AI Safety Act | July 1, 2027 |
| Arizona | Board of Behavioral Health Examiners consent rule | January 1, 2027 |
| Colorado | HB 1195 (AI therapy) | 2026 wave — see the Colorado note below |
| Maine | LD 2082 | 2026 wave |
| Rhode Island | 2026 AI-therapy measure | 2026 wave |
| Vermont | 2026 AI-therapy measure | 2026 wave |
The 2026–2027 wave of AI-therapy and behavioral health AI measures.
The trend line is unambiguous. Reporting compiled by the Transparency Coalition counted 14 new health-AI laws across 11 states in 2026 as of late July, from more than 40 bills introduced across 25 states — five of them specifically on AI therapy chatbots. Holland & Knight's 2026 survey tracks the same acceleration. Any architecture you ship this year needs per-state policy configuration, not a single global setting.
Titles, Marketing, and Design Elements — Where Practices Trip First
The most common violation in this space is not a rogue model. It is a product name, a homepage headline, or an avatar wearing a white coat. California legislated against exactly that.
AB 489, effective January 1, 2026, bars AI systems from using terms, post-nominal letters, or design elements that imply licensure — "doctor," "M.D.," "nurse," "clinician-guided," and their equivalents. Enforcement runs through the licensing boards, and each use is a separate violation. The California Board of Psychology has published an advisory on it. Note that "design elements" reaches beyond copy: a stethoscope icon, a clinical-badge motif, or a credential-styled signature block in an automated email are all in scope.
SB 243, signed October 13, 2025 and operative January 1, 2026, governs companion chatbots. Where a reasonable person could be misled into believing they are talking to a human, a clear and conspicuous AI notification is required, and a suicide and self-harm crisis protocol is mandatory. The teeth are in the remedy: SB 243 creates a private right of action for actual damages or $1,000 per violation, plus fees. Annual reporting obligations begin July 1, 2027. A practice-owned chatbot that drifts into companionship territory — check-in messages, supportive conversation between sessions — is squarely in the frame.
Delaware HB 191, passed April 23, 2026, closes the identity question from the licensure side: no nonhuman entity, including an AI agent, may be licensed or certified as a nurse, APRN, LPN, physician, or physician assistant, or use those protected titles. Illinois adds the marketing prohibition directly — you may not advertise "AI therapy."
One adjacent California rule is worth understanding because it draws the same clinical-versus-administrative line the WOPR Act does. AB 3030, effective January 1, 2025, requires an AI disclaimer and human-contact instructions on generative-AI communications containing patient clinical information — and expressly excludes "administrative matters, including… appointment scheduling, billing, or other clerical or business matters." The exclusion is the point: California, like Illinois, treats the administrative layer as a different regulatory object from the clinical one.
Informed Consent as an Engineering Requirement, Not a Form
Behavioral health is converging on documented, specific, revocable consent as the precondition for any AI use that touches the client. Illinois requires written client consent for supplementary uses of AI. Maine's LD 2082 limits mental health professionals to administrative AI and requires consent for ambient listening. Arizona's Board of Behavioral Health Examiners rule, effective January 1, 2027, requires documented informed consent before using AI, machine learning, or human-simulation modalities.
The engineering implication is that consent has to be a queryable data structure, not a PDF in a filing cabinet. Every agent action that touches a client should check the consent ledger first, and withdrawal has to be enforced in code within minutes — not "handled by the front desk."
| Consent element | What it must actually say or do | Driven by |
|---|---|---|
| What the agent is | Plainly: software, not a clinician. No titles, no post-nominals, no design elements implying licensure | California AB 489; Delaware HB 191 |
| What it does and does not do | Enumerate the administrative functions. State explicitly that it does not provide therapy, assess emotional state, or make clinical decisions | Illinois WOPR Act; Nevada AB 406 |
| Whether sessions are recorded | Named, specific, revocable consent to ambient recording — obtained before the first recorded session, re-affirmed when the tool changes | All-party-consent recording states; Maine LD 2082 |
| Who the vendor is and what they hold | Vendor named, BAA signed, retention period stated, model-training use disclosed | HIPAA business associate obligations |
| How to reach a human | A stated path to a live person, and a stated crisis path, on every client-facing surface | California SB 243 crisis protocol |
| That consent can be withdrawn | Withdrawal must be operationally real — a documented off-switch per client, not a policy sentence | Arizona BBHE rule (eff. Jan 1, 2027) |
The six consent elements Frenchy Digital builds into every behavioral health agent engagement.
If withdrawing consent requires a human to remember to do something, consent is not implemented. It is documented. Those are different systems and only one of them survives an investigation.
— Frenchy Digital compliance principle
Ambient Documentation in the Therapy Room
Ambient scribing is expressly permitted in Illinois and is the single highest-value permitted use case for a therapy practice. It is also the one with the most legal surface area, because a therapy session is a recording of the most sensitive conversation most people will ever have.
Start with the preemption point, because it is the one practices get wrong. HIPAA generally treats scribe use as a permitted treatment activity, which means no separate HIPAA authorization is required. That does not preempt state wiretap law. Roughly 13 states — including California, Illinois, Pennsylvania, Florida, and Massachusetts — require all parties to consent to a recording. The American Bar Association's health law section has written up the interaction in detail.
The cautionary example is now in active litigation. Washington et al. v. Sutter Health et al., N.D. Cal. No. 4:26-cv-03012, filed April 2026, is a proposed class action that alleges Sutter Health and MemorialCare used an ambient AI scribe to record patient visits without consent. The complaint alleges violations of the California Invasion of Privacy Act, the Confidentiality of Medical Information Act, the Unfair Competition Law, the federal Wiretap Act, and common-law invasion of privacy. CIPA carries $5,000 in statutory damages per interception. An earlier proposed class action filed in November 2025 alleged that more than 100,000 encounters were recorded with boilerplate consent language in the notes that was untrue. These are complaint-stage allegations and remain unproven — but the arithmetic of per-interception statutory damages against a class of recorded sessions is why we treat written consent as an architectural requirement rather than a legal preference. Reporting is here.
Add the psychotherapy-note dimension. HIPAA gives psychotherapy notes — the clinician's process notes kept separate from the rest of the record — stronger protection than ordinary PHI. Before you enable a tool, you need to know whether it is drafting a progress note, a psychotherapy note, or both, and where each artifact lands in your record system.
| Question to answer before you record a session | The standard we hold vendors to |
|---|---|
| Is my state an all-party-consent state? | Roughly 13 states — including California, Illinois, Pennsylvania, Florida, and Massachusetts — require every party to consent to a recording. HIPAA's treatment-activity permission does not preempt state wiretap law |
| Is the audio retained, and for how long? | Get the retention period in writing. Vendor-stated practices differ sharply: Microsoft's Dragon Copilot states it retains audio, transcript, and note for 30 days then deletes; Nabla states it does not store audio or transcripts server-side |
| Is a BAA in place at the tier I am actually buying? | Free and self-serve tiers frequently do not carry a BAA. No BAA, no ePHI — this is the single most common failure we find in small-practice deployments |
| Is my session audio used to train models? | Require a written no, or a written description of the opt-out and how it is enforced |
| Is the draft a progress note, a psychotherapy note, or both? | HIPAA gives psychotherapy notes kept separate from the rest of the record stronger protection than ordinary PHI. Know which artifact your tool is producing before you turn it on |
| Who reviews and signs, and how long does that take? | The clinician, every time, with enough time to actually read the draft. Review that is instantaneous across a full panel is not review |
The vendor diligence checklist for ambient documentation in behavioral health. Retention, BAA, and training use are the three questions that decide the purchase.
What ambient scribing costs a small practice in 2026
No independent pricing survey exists for this category. Every figure below is vendor-published or competitor-blog sourced and should be verified with a quote before it enters a budget. Self-serve and solo tiers run roughly $39–$99 per provider per month; Heidi raised its main paid tier from about $90 to $150 per month in February 2026; Suki has been reported in the $299–$399 per-provider-per-month mid-market band. The AAFP has estimated roughly $150–$200 per provider per month for family practices.
The trap is the free tier. Free and entry-level plans frequently do not carry a BAA, which makes them unusable for ePHI regardless of how good the transcription is. Confirm the BAA at the exact tier you intend to buy, in writing, before a single session is recorded.
Crisis Escalation: The Non-Negotiable
Any client-facing agent in behavioral health needs a hard escalation path to a human. Shipping one without it is both a clinical failure and a legal one, and in California it is now specifically actionable — SB 243 makes a suicide and self-harm crisis protocol mandatory for companion chatbots and attaches a private right of action with $1,000-per-violation statutory damages.
The design is harder than it sounds, because of a constraint most vendors miss. The obvious implementation is a model that assesses risk from the conversation. In Illinois, that is itself prohibited — the WOPR Act bars AI from assessing a client's emotional state. So the escalation trigger cannot be an AI risk assessment. It has to be a conservative, deterministic tripwire that errs heavily toward false positives, ends the automated interaction rather than continuing it, and routes to a named human with a stated response time.
- Deterministic tripwire, not a risk score: Keyword and intent matching tuned for over-triggering. No emotional-state inference, no severity scoring, no confidence-weighted continuation.
- Terminate, do not de-escalate: The agent's job on trigger is to stop being the interface. It surfaces crisis resources and the practice's human contact path, then hands off. It does not attempt supportive conversation.
- Named human, stated response time: 'A clinician will follow up' is not a protocol. Who, within what window, through what channel, with what after-hours fallback — written down and staffed.
- Always-visible human path: Every client-facing surface carries a route to a live person, independent of whether a trigger fired. California AB 3030 requires human-contact instructions on clinical GenAI communications; make it universal.
- Logged and reviewed: Every trigger, every non-trigger that a clinician later flags, every response time — logged, sampled, and reviewed on a schedule. This is your evidence that the protocol is real.
- Tested before launch, not after: Red-team the tripwire with realistic phrasing, including indirect disclosure, before a single real client touches the system.
What Actually Gets Paid For in 2026
Two reimbursement facts materially change a behavioral health practice's 2026 and 2027 planning. Neither of them pays for an AI agent, and understanding why is worth more than any vendor ROI deck.
First: Digital Mental Health Treatment codes exist and are live. The CY2026 Medicare Physician Fee Schedule final rule established HCPCS G0552 for device supply and onboarding, G0553 for the first 20 minutes of monthly treatment management, and G0554; CMS also finalized expansion to ADHD devices. These are device-and-clinician-time codes. They pay for supplying a digital mental health treatment device and for the clinician time spent managing that treatment. They do not pay for an ambient scribe, a scheduling agent, or any administrative automation.
Second: behavioral telehealth has a cliff on the calendar. Medicare telehealth flexibilities lapsed on February 1, 2026 during the shutdown and were restored retroactively by the Consolidated Appropriations Act, 2026, signed February 3, 2026 — CMS states they apply "as if there hadn't been a temporary lapse." For behavioral and mental health specifically, there is no in-person requirement through December 31, 2027. Starting January 1, 2028, the in-person cadence resumes: a visit within the six months prior, and every 12 months thereafter. See the CMS telehealth FAQ.
On the general question of AI payment, the honest answer is that there is none. In the CY2026 PFS, CMS solicited comment on paying for software and algorithms under the fee schedule, noting that they are "not well accounted for" — and finalized no general AI payment pathway. Ambient scribes, AI coding, and administrative agents are cost-side investments. Any vendor presenting them as a revenue line is describing downstream capture effects, not a reimbursement mechanism, and should be asked to say so.
Reference Architecture for a Behavioral Health Practice Agent
Everything above resolves into eight components. This is the baseline Frenchy Digital ships on behavioral health engagements, and it is deliberately conservative — in this specialty the cost of a false negative in a compliance control is a licensure matter.
| Component | What it does | Implementation note |
|---|---|---|
| Disclosure layer | AI identity stated at the start of every client-facing interaction, in the medium of the interaction | Spoken on voice, displayed on chat, printed at the top of written output |
| Scope guard | A hard allowlist of permitted intents; everything else routes to a human | Deny by default — clinical intents never reach the model's generative path |
| Consent ledger | Per-client, per-purpose, timestamped, revocable | Queried before any recording or supplementary use; withdrawal is enforced in code |
| Crisis tripwire | Conservative keyword and intent detection that ends the interaction and routes to a human | Deliberately not an AI risk assessment — Illinois bars emotional-state assessment |
| Human review step | Every draft note, letter, and outbound clinical-adjacent message is reviewed and signed | Review time and override rate are logged, not assumed |
| Audit log | Append-only record of every action, actor, timestamp, and model version | The artifact you hand a board investigator or a payer auditor |
| BAA-backed infrastructure | Signed BAA with every vendor touching ePHI; encryption in transit and at rest | Never described as 'HIPAA-certified' — no such certification exists |
| Kill switch | Per-workflow and per-client disable, effective immediately | A statute changes, a client withdraws consent, or a vendor changes terms |
The Frenchy Digital reference architecture for a behavioral health practice agent, 2026.
A word on the HIPAA layer, because the terminology matters. There is no such thing as a "HIPAA-certified" vendor or product — no certification exists. What exists is a HIPAA-compliant posture: a signed business associate agreement with every vendor that touches ePHI, and Security Rule administrative, physical, and technical safeguards you can evidence. The 2003 Security Rule is what governs an AI agent touching ePHI today. The Security Rule NPRM published January 6, 2025 would, as proposed, make all implementation specifications required, mandate MFA and encryption of ePHI at rest and in transit, and add annual audits and penetration testing — but it has moved to the Unified Agenda's long-term actions with a projected final action of July 2027. It is neither finalized nor withdrawn, and it is not a current obligation.
Human-in-the-loop is a control, and controls get measured
The OIG's February 2026 Medicare Advantage Industry Compliance Program Guidance explicitly named as potentially abusive the practice of "querying physicians via electronic medical record platforms, including prompts generated by artificial intelligence algorithms, to add risk-adjusting diagnoses." The relevance for a behavioral health practice is the underlying theory rather than the risk-adjustment specifics: a review step that exists on paper but is performed at a speed no human could actually read at is not review.
So we instrument it. Documented review time per artifact, override and rejection rates by clinician and by workflow, append-only audit logs, and periodic sampled QA. If a board or a payer asks how you know a human reviewed the output, the answer should be a query, not an assurance.
Limitations and Honest Failure Modes
The evidence base for ambient documentation is genuinely mixed, and in behavioral health a few of the null findings are more relevant than the positive ones. Here is the field as it actually stands.
| Study / source | What it found | How to read it |
|---|---|---|
| NEJM AI randomized trial (Dec 2025, UCLA) | 238 physicians, 14 specialties, three arms. Nabla reduced time-in-note 9.5% vs control (P=0.02); DAX showed no significant reduction (P=0.66). Both improved burnout metrics. Clinically significant inaccuracies noted occasionally; one mild adverse event | The strongest design in the literature, and it does not support a uniform time-savings claim |
| JAMA Network Open (Aug 21, 2025) | Mass General Brigham + Emory, n=1,430 clinicians. Burnout prevalence at MGB fell 52.6% → 30.7% at 84 days; at Emory, positive documentation impact on well-being rose 1.6% → 32.3% | Survey-based, response rates 22–30% at MGB and 11% at Emory, self-reported use. Encouraging, not causal |
| NEJM Catalyst (Jun 2025, The Permanente Medical Group) | 7,260 physicians, ~2.5M encounters; an estimated 15,791 hours of documentation time saved | Large and real — but see the next row for the per-encounter reality |
| Reported in npj Digital Medicine (2026) | The Permanente Medical Group deployment saved roughly 18 seconds per appointment versus non-users. An Intermountain Health matched-cohort analysis found no statistically significant productivity gains. MGB median total EHR time fell 5.6 minutes per appointment | The honest counterweight. Aggregate hours look impressive; per-encounter gains are modest and inconsistent |
| Note-quality pilot (356 notes) | Omissions 18%, hallucinations 11.5%, accidental inclusions 9.3%, bias 1.1%. Most errors mild to moderate, but 5.3% of notes with errors were rated potentially seriously harmful | Your review step is a safety control, not an editorial nicety |
| Koenecke et al., ACM FAccT 2024 (13,140 segments) | 1.4% of audio segments produced a speech-to-text hallucination; 38% of hallucinations contained explicit harms. Disproportionately affects speakers with longer non-vocal pauses | Directly relevant to psychotherapy, where silence is clinical content rather than dead air |
| PHTI (Mar 25, 2025) | Ambient scribes reduce cognitive load and likely burnout, but do not uniformly reduce after-hours documentation or produce financial returns; adoption uneven; few peer-reviewed studies with mixed results | The fairest one-sentence summary of the field as it stands |
Ambient documentation evidence, positive and null, as of August 2026. Sources: NEJM AI, JAMA Network Open, NEJM Catalyst, npj Digital Medicine, note-quality evaluation, Koenecke et al., PHTI.
Two further constraints from independent research. KLAS Arch Collaborative's ambient speech work found that over 80% of providers declined to see more patients after adopting ambient tools, with only 18% wanting added volume — which invalidates the volume-based ROI model that most vendor business cases rest on. KLAS's 2026 collaborative work also found that under 25% of AI-adopting clinicians said they received adequate training, and that satisfaction plateaus past roughly four AI tools. Buy fewer tools, train properly, and model the return as reclaimed clinician time rather than added throughput.
A separate 2026 JMIR research letter documented ambient scribes propagating interpreter errors — relevant to any practice serving clients in a language other than the clinician's. And note that no FDA guidance names AI scribes or ambient documentation specifically; none exists. Administrative agents and scribes are generally not devices, so the binding federal constraints are HIPAA and, where the tool is embedded in certified health IT, ONC's decision-support transparency requirements — not FDA device law.
Cost Bands and Timelines for a Behavioral Health Practice Agent
These are Frenchy Digital's 2026 bands for behavioral health engagements. They include the compliance work — state applicability review, consent artifacts, crisis design, audit logging — because in this specialty that work is not an add-on, it is most of the build.
| Engagement | Range | Timeline | Typical scope |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | Workflow mapping, state-by-state applicability review, permitted/prohibited classification of every proposed use case, consent artifact drafting, written fixed-price phased proposal |
| Single-workflow agent (intake, reminders, eligibility) | $25k–$65k | 4–9 weeks | One administrative workflow end to end: agent, disclosure and consent flow, human escalation, audit logging, BAA-backed infrastructure, staff runbook |
| Multi-workflow practice automation with EHR integration | $65k–$160k | 9–16 weeks | Scheduling, intake, eligibility, and documentation handoff wired into the practice's EHR; role-based access; override and rejection-rate tracking; clinician review dashboard |
| Multi-site / regulated build, HIPAA posture + HITL + audit logging | $160k–$400k+ | 14–24 weeks | Group practice or multi-state telehealth: per-state policy configuration, documented human-in-the-loop controls, append-only audit log, incident runbook, evidence pack for payer and board review |
Frenchy Digital cost bands for behavioral health AI agent engagements, 2026.
Senior-led delivery is priced at $150–$225 per hour. Ongoing retainers run $2,500–$9,500 per month and cover statute monitoring as new state laws take effect, prompt and policy updates, vendor BAA reviews, escalation-log QA, and a quarterly technical business review. Every engagement carries a 30-day post-launch warranty, and you receive a written scope and fixed-price phased proposal within 5 business days of the discovery call.
Red Flags When Buying an AI Agent for a Behavioral Health Practice
The behavioral health AI market has attracted vendors whose product was designed for a general medical practice and repositioned for therapists without re-reading the statutes. These are the signals we tell practice owners to watch for, whoever they ultimately hire.
| Red flag | Why it matters |
|---|---|
| Vendor markets a 'therapy' or 'AI counselor' product to your practice | Illinois bars marketing AI therapy outright. If the vendor's own homepage is non-compliant, their product will be too |
| No state-by-state applicability analysis in the proposal | This is not a uniform market. A design lawful in one licensure state can be prohibited in the next one you add |
| The agent is named or styled to imply licensure | California AB 489 makes each use a separate violation; Delaware HB 191 bars protected titles for nonhuman entities |
| Crisis handling is described as 'the model detects risk' | That is emotional-state assessment, which Illinois prohibits — and it is a fragile clinical control regardless |
| No BAA at the tier you are actually buying | Free and entry tiers routinely lack one. Without a BAA the tool cannot touch ePHI, whatever the demo showed |
| Consent is a checkbox buried in an intake packet | In an all-party-consent state, and against the claims pled in the Sutter/MemorialCare complaint, buried consent is the exposure |
| Audio retention, deletion, and training use are not in writing | Retention period, BAA, and model-training use are the three questions. Verbal answers are not answers |
| ROI is modeled on seeing more clients per day | KLAS found over 80% of providers declined to see more patients after adopting ambient tools; only 18% wanted added volume |
| No audit log, no override tracking, no review-time capture | Human-in-the-loop is a compliance control. If it is not measured, you cannot demonstrate it happened |
| Vendor keeps the code, the prompts, or the accounts | You will be renting your own practice infrastructure. Insist on ownership transfer in the SOW |
The Frenchy Digital red-flag checklist for behavioral health AI buyers, 2026.
Ask a vendor to point at the specific statute that permits the use case they are selling you. If they answer with a compliance badge instead of a citation, you are the one carrying the risk — the license on the wall is yours, not theirs.
— Frenchy Digital buyer's principle
Working with Frenchy Digital on a Behavioral Health Practice Agent
Frenchy Digital is a senior-led, Black-owned Los Angeles agency. We build administrative and documentation agents for healthcare practices. We do not build systems that deliver care, assess emotional state, or substitute for a licensed clinician's judgment — in behavioral health that is not a positioning choice, it is what the statutes require.
- State applicability review first: Before any build decision, every proposed use case is classified permitted or prohibited against the statutes in every state where you hold a license, with the citation attached. That review is the first deliverable, not an afterthought.
- Written scope in 5 business days: A 60-minute structured discovery call, then a written scope document and fixed-price phased proposal within 5 business days. No open-ended hourly billing.
- Senior engineers on every engagement: Healthcare work does not get staffed with juniors. Every consent ledger, escalation path, and audit log is built by someone who has shipped a regulated system before.
- Compliance controls are instrumented: Review time, override rates, escalation triggers, and response times are logged and queryable. Human-in-the-loop is only a control if you can prove it happened.
- Your EHR, your practice management system: We integrate with what you already run rather than migrating you onto something new. Behavioral health practices do not need a platform change to get an intake agent.
- Statute monitoring on retainer: The 2026 wave lands mostly in 2027. Retained clients get policy updates as Tennessee, Oregon, Idaho, Nebraska, and Arizona take effect, not a support ticket after the fact.
- Full ownership transfer: Source code, prompts, policies, infrastructure accounts, and IP transfer to your practice at delivery, with a 30-day post-launch warranty. No vendor lock-in.
Book a discovery call at calendly.com/frenchydigital/discovery-call or call +1 (424) 272-5601.
What we will tell you no about
A client-facing conversational agent that provides supportive dialogue between sessions. An automated risk-screening layer that scores client messages. A "check in with your therapist's AI" feature. An avatar with a clinical name or a credentialed visual identity. A chatbot deployed uniformly across a multi-state telehealth panel without per-state configuration.
Each of those has been pitched to practices we work with in the last year. Each of them runs into Illinois, Nevada, California, or Delaware — and the enforcement lands on the licensed professional, not the software vendor. The permitted list is large enough to build a real business case on. We build on that.
The Practice Owner's Pre-Launch Checklist
Before any behavioral health agent handles a real client interaction, you should be able to answer all ten of these in writing.
- 1.Use-case classification: Every function the agent performs is classified permitted or prohibited against the statute in every state where you hold a license, with the citation recorded.
- 2.Naming and marketing audit: Product name, avatar, website copy, intake packet, reminder templates, and voicemail greeting reviewed against California AB 489 and Delaware HB 191.
- 3.Written consent: Specific, revocable, per-purpose consent captured in a queryable ledger, covering ambient recording separately from other AI uses.
- 4.All-party-consent check: Recording consent verified against the wiretap law of every state your clients sit in — not just where you practice.
- 5.BAA at the purchased tier: Signed BAA with every vendor touching ePHI, verified at the exact plan you bought, with retention period and training use in writing.
- 6.Crisis path: Deterministic tripwire, immediate termination and human handoff, named responder, stated response time, after-hours fallback, red-teamed before launch.
- 7.Human review step: Every draft note, letter, and clinical-adjacent message reviewed and signed, with review time and override rate logged.
- 8.Audit log: Append-only, capturing actor, action, timestamp, and model version for every agent operation.
- 9.Kill switch: Per-workflow and per-client disable, tested, with a documented owner.
- 10.Statute watch: A named person or retainer responsible for the 2027 effective dates in Oregon, Idaho, Nebraska, Arizona, and Colorado.
Build the Permitted Use Cases Properly
Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned Los Angeles agency. You leave with a state-by-state applicability review of your proposed use cases and a fixed-price phased proposal within 5 business days.
Planning an AI Agent for Your Behavioral Health Practice?
Book a free 60-minute discovery call with Frenchy Digital, a senior-led Black-owned Los Angeles agency. You leave with a state-by-state applicability review of your use cases and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1IDFPR — Illinois prohibits AI therapy (WOPR Act, HB 1806)↗
- 2California Board of Psychology — AB 489 advisory↗
- 3California AB 3030 — GenAI in patient communications (bill text)↗
- 4CMS — Medicare telehealth FAQ (updated Feb 26, 2026)↗
- 5HHS — HIPAA home↗
- 6Federal Register — HIPAA Security Rule NPRM (90 FR 898)↗
- 7AMA — Augmented intelligence in medicine↗
- 8AMA — Policies to ensure AI supports, not replaces, physician judgment (June 2026)↗
- 9AMA — 2026 Physician AI Sentiment Report↗
- 10NEJM AI — Randomized trial of ambient documentation (Dec 2025)↗
- 11JAMA Network Open — Ambient documentation and burnout (Aug 2025)↗
- 12NEJM Catalyst — Ambient AI at The Permanente Medical Group (Jun 2025)↗
- 13PHTI — Assessment of AI scribes (Mar 2025)↗
- 14Note-quality evaluation of AI-generated clinical notes↗
- 15Koenecke et al. — Speech-to-text hallucinations (ACM FAccT 2024)↗
- 16npj Digital Medicine — Ambient documentation outcomes (2026)↗
- 17American Bar Association — Ambient AI scribes: privacy and cybersecurity↗
- 18Sutter Health / MemorialCare AI scribe class action (reporting)↗
- 19Holland & Knight — States continue efforts to regulate AI in health care↗
- 20Colorado General Assembly — SB 26-189↗

